STIGQter STIGQter: STIG Summary:

Google Android 16 COPE Security Technical Implementation Guide

Version: 1

Release: 3 Benchmark Date: 13 May 2026

CheckedNameTitle
SV-276850r1140342_ruleGoogle Android 16 must be configured to enable audit logging.
SV-276851r1140345_ruleGoogle Android 16 must be configured to enforce a minimum password length of six characters.
SV-276852r1140348_ruleGoogle Android 16 must be configured to not allow passwords that include more than four repeating or sequential characters.
SV-276853r1140351_ruleGoogle Android 16 must be configured to lock the display after 15 minutes (or less) of inactivity.
SV-276854r1140354_ruleGoogle Android 16 must be configured to not allow more than 10 consecutive failed authentication attempts.
SV-276855r1140357_ruleGoogle Android 16 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store].
SV-276856r1140360_ruleGoogle Android 16 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].
SV-276857r1140363_ruleGoogle Android 16 allowlist must be configured to not include applications with the following characteristics: - Backs up mobile device (MD) data to non-DOD cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DOD servers; - Voice assistant application if available when MD is locked; - Voice dialing application if available when MD is locked; - Allows synchronization of data or applications between devices associated with user; - Payment processing; - Allows unencrypted (or encrypted but not FIPS 140-2/140-3 validated) data sharing with other MDs or printers; - Backs up own data to a remote system; - Renders TV shows and movies.
SV-276858r1140366_ruleGoogle Android 16 allowlist must be configured to not include artificial intelligence (AI) applications that process device data in the cloud, including Google Gemini.
SV-276859r1140369_ruleGoogle Android 16 must be configured to not display the following (work profile) notifications when the device is locked: [selection: a. email notifications b. calendar appointments c. contact associated with phone call notification d. text message notification e. other application-based notifications f. all notifications].
SV-276860r1140372_ruleGoogle Android 16 must be configured to disable trust agents.
SV-276861r1140375_ruleGoogle Android 16 must be configured to disable developer modes.
SV-276862r1140378_ruleGoogle Android 16 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device.
SV-276863r1140381_ruleGoogle Android 16 must be configured to generate audit records for the following auditable events: Detected integrity violations.
SV-276864r1140384_ruleGoogle Android 16 must be configured to disable USB mass storage mode.
SV-276865r1140387_ruleGoogle Android 16 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.
SV-276866r1140390_ruleGoogle Android 16 must be configured to not allow backup of [all applications, configuration data] to remote systems.
SV-276867r1140393_ruleGoogle Android 16 must be configured to enable authentication of personal hotspot connections to the device using a preshared key.
SV-276868r1140396_ruleGoogle Android 16 must be configured to disable exceptions to the access control policy that prevent [selection: application processes, groups of application processes] from accessing [selection: all, private] data stored by other [selection: application processes, groups of application processes].
SV-276869r1140399_ruleGoogle Android 16 must be configured to disable multiuser modes.
SV-276870r1140667_ruleGoogle Android 16 must be configured to disable Bluetooth or configured via User Based Enforcement (UBE) to allow Bluetooth for only Headset Profile (HSP), Hands-Free Profile (HFP), and Serial Port Profile (SPP).
SV-276871r1140405_ruleGoogle Android 16 must be configured to disable ad hoc wireless client-to-client connection capability.
SV-276872r1140408_ruleGoogle Android 16 users must complete required training.
SV-276873r1140411_ruleGoogle Android 16 must be configured to disable Wi-Fi Sharing.
SV-276874r1140414_ruleGoogle Android 16 must be configured to enforce a password for Wi-Fi and Bluetooth hotspot if approved for use by the authorizing official (AO). If not approved for use, Wi-Fi and Bluetooth hotspot must be disabled.
SV-276875r1140417_ruleGoogle Android 16 must have the DOD root and intermediate PKI certificates installed.
SV-276876r1140420_ruleThe Google Android 16 work profile must be configured to prevent users from adding personal email accounts to the work email app.
SV-276877r1140423_ruleThe Google Android 16 work profile must be configured to enforce the system application disable list.
SV-276878r1140426_ruleGoogle Android 16 must be provisioned as a fully managed device and configured to create a work profile.
SV-276879r1140429_ruleThe Google Android 16 work profile must be configured to disable automatic completion of workspace internet browser text input.
SV-276880r1140679_ruleThe Google Android device must be configured to disable Wi-Fi Aware for Work Profile apps.
SV-276882r1140438_ruleAndroid 16 devices must have the latest available Google Android 16 operating system installed.
SV-276883r1140441_ruleAndroid 16 devices must be configured to disable the use of third-party keyboards.
SV-276884r1140444_ruleAndroid 16 devices must be configured to enable Common Criteria (CC) Mode.
SV-276885r1140447_ruleGoogle Android 16 must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)].
SV-276886r1140450_ruleGoogle Android 16 must allow only the administrator (EMM) to install/remove DOD root and intermediate PKI certificates.
SV-276887r1140453_ruleGoogle Android 16 must allow only the administrator (MDM) to perform the following management function: Disable Phone Hub.
SV-276888r1140456_ruleGoogle Android 16 must be configured to disable "Private Space" use.
SV-276889r1188340_ruleGoogle Android 16 must disable the user's ability to wipe the device.
SV-276891r1140465_ruleGoogle Android 16 must disable wireless printing.
SV-276892r1140468_ruleGoogle Android 16 must disable screen capture.
SV-276893r1140471_ruleGoogle Android 16 devices must have a Mobile Threat Detection (MTD) app installed.
SV-276894r1140474_ruleGoogle Android 16 must implement the management setting: disable Camera.